CVE-2013-4158
published 2019-12-11CVE-2013-4158: smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.25%
65.9th percentile
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | smokeping | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| smokeping | smokeping | < 2.6.9 | 2.6.9 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gj7j-7773-fpw5: smokeping before 2
ghsa_unreviewed·2022-05-05·CVSS 4.3
CVE-2013-4158 [MEDIUM] GHSA-gj7j-7773-fpw5: smokeping before 2
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
OSV
CVE-2013-4158: smokeping before 2
osv·2019-12-11·CVSS 4.3
CVE-2013-4158 [MEDIUM] CVE-2013-4158: smokeping before 2
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
Debian
CVE-2013-4158: smokeping - smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
vendor_debian·2013·CVSS 4.3
CVE-2013-4158 [MEDIUM] CVE-2013-4158: smokeping - smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4158 smokeping: XSS flaw (incomplete fix for CVE-2012-0790)
bugzilla·2013-07-20·CVSS 4.3
CVE-2013-4158 [MEDIUM] CVE-2013-4158 smokeping: XSS flaw (incomplete fix for CVE-2012-0790)
CVE-2013-4158 smokeping: XSS flaw (incomplete fix for CVE-2012-0790)
Seth Arnold ([email protected]) reports:
Hello Kurt, Steve, all,
I am requesting a 2012 CVE for an incomplete security fix in smokeping,
fixed in version 2.6.9.
CVE-2012-0790 was assigned to smokeping for XSS flaws.
The fix for CVE-2012-0790 in smokeping 2.6.7 was incomplete. The
filtering used this blacklist:
$mode =~ s/[<>&%]/./g;
The version in 2.6.9 uses the following blacklist:
my $xssBadRx = qr/[<>%&'";]/;
(', ", and ; have been added. When it is used, blacklist chars are now
turned to _ rather than . ) The 2.6.9 version prevents escaping via " characters.
The incomplete fix is in 2.6.7 and 2.6.8.
This flaw was discovered by Florian Weimer [1] in 2012 and brought to
our attention [2] in 2013.
The
Bugzilla
CVE-2013-4158 CVE-2013-4168 smokeping: various flaws [fedora-all]
bugzilla·2013-07-20·CVSS 6.1
CVE-2013-4158 [MEDIUM] CVE-2013-4158 CVE-2013-4168 smokeping: various flaws [fedora-all]
CVE-2013-4158 CVE-2013-4168 smokeping: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multipl
http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113987.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-August/114008.htmlhttp://www.openwall.com/lists/oss-security/2013/07/20/2http://www.securityfocus.com/bid/61371https://access.redhat.com/security/cve/cve-2013-4158https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4158https://exchange.xforce.ibmcloud.com/vulnerabilities/85887https://security-tracker.debian.org/tracker/CVE-2013-4158http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113987.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-August/114008.htmlhttp://www.openwall.com/lists/oss-security/2013/07/20/2http://www.securityfocus.com/bid/61371https://access.redhat.com/security/cve/cve-2013-4158https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4158https://exchange.xforce.ibmcloud.com/vulnerabilities/85887https://security-tracker.debian.org/tracker/CVE-2013-4158
2019-12-11
Published